oh guh I still need to fix the certs for some of my stuff
(kemona_halftau)
@skydotbit i wish ssl certificates were permanent, or at the very least didnt depend on the date/time
i honestly dont get why having a certificate for a domain name you used to own when someone else buys it later on is much of a security issue
@kemona_halftau @skydotbit because then anyone who has previously owned a domain (or had control of it at any point) can impersonate anyone else who has it in the future. with the current system where any cert signed by a CA for the right hostname is automatically trusted (and not everything checks revocation (for example neither curl nor wget complains about https://revoked.badssl.com/)), that would be a terrible idea.